Vulnerabilidades em Elastic

352 resultados
Análise Vexday

Com 233 CVEs catalogadas, o ecossistema Elastic apresenta taxa de exploração ativa em linha com a média geral do catálogo, o que não elimina pontos de atenção relevantes. O CVE-2019-7609, única entrada confirmada no CISA KEV, carrega EPSS de 0,9534 — valor extremamente elevado que indica alta probabilidade de exploração ativa e deve ser prioridade absoluta para equipes que ainda não aplicaram a correção correspondente. O tipo de falha mais frequente, CWE-79 (Cross-Site Scripting), sugere que controles de sanitização de entrada e saída merecem atenção sistemática no ciclo de desenvolvimento e hardening das implantações. As 17 CVEs surgidas nos últimos 90 dias e a existência de 3 vulnerabilidades com PoC pública reforçam a necessidade de monitoramento contínuo, especialmente em ambientes expostos.

CVE-2026-72682MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-72674MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-72639MEDIUMMemory Allocation with Excessive Size Value in Elasticsearch Highlighting Leading to Denial of ServiceEPSS 0.3%CVE-2026-72651MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-78588MEDIUMAllocation of Resources Without Limits or Throttling in Filebeat Leading to Denial of ServiceEPSS 0.3%CVE-2026-72667MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-72644MEDIUMUncaught Exception in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-72652MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-72663MEDIUMInefficient Algorithmic Complexity in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-72687MEDIUMMemory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of ServiceEPSS 0.3%CVE-2026-72659MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-63142MEDIUMIncomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request ForgeryEPSS 0.3%CVE-2026-63259MEDIUMAuthorization Bypass Through User-Controlled Key in Kibana Leading to Information DisclosureEPSS 0.3%CVE-2026-78594MEDIUMImproper Handling of Highly Compressed Data in APM Server Leading to Persistent Denial of ServiceEPSS 0.3%CVE-2026-33461HIGHIncorrect Authorization in Kibana Fleet Leading to Information DisclosureEPSS 0.3%CVE-2021-22136In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.session.idleTimeout settinEPSS 0.3%CVE-2026-72664MEDIUMMissing Authorization in Kibana Leading to Unauthorized Execution of Endpoint Response ActionsEPSS 0.3%CVE-2026-72666MEDIUMAuthorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Query Execution on Managed HostsEPSS 0.3%CVE-2026-72657MEDIUMAuthorization Bypass Through User-Controlled Key in Fleet Server Leading to Information DisclosureEPSS 0.3%CVE-2025-25010MEDIUMKibana privilege escalation via reporting_user roleEPSS 0.3%